Skip to main content

Overview

A scope is one permission on one resource, named resource:action, and a role bundles scopes. You assign a role to a user or a group either organization-wide or for a single workspace, and Tracecat computes each user’s effective permissions from those assignments.

Built-in roles

Tracecat seeds six built-in roles into every organization at startup. Tracecat rejects changes to a built-in role’s scopes and rejects deleting it, so create a custom role when the built-in set does not fit. The Scopes column counts the current definition. Startup seeding adds scopes a built-in role is missing and removes none, so an organization created before a scope was renamed also keeps the old name. organization-owner and organization-admin reach every workspace in the organization without a workspace membership. Every other user needs a workspace role, assigned on that workspace or organization-wide, and organization-member on its own grants no workspace resource scope. Built-in roles

Assignments

An assignment binds one role to one user or one group, either organization-wide or for a single workspace. An organization-wide assignment applies in every workspace, and a workspace assignment grants nothing outside that workspace. A role that holds any org:* scope is an organization role and can only be assigned organization-wide. Every other role is a workspace role: assign it on one workspace, or organization-wide to grant it in every workspace. Tracecat rejects a role edit that would switch a role between the two while it is assigned or offered in a pending invitation. Assignments created before this rule existed keep working until you change or remove them; editing one requires picking a role that fits its scope. A user’s effective scopes are the union of their direct assignments and the assignments of every group they belong to. A user with workspace-viewer directly and a group assignment of workspace-editor in the same workspace holds every workspace-editor scope there. Each user holds at most one direct assignment per workspace and at most one organization-wide direct assignment, and the same limit applies to each group. Tracecat refuses a second assignment for the same user and workspace with User already has an assignment for this workspace, and for the same group with Group already has an assignment for this workspace — change the role on the existing assignment instead. You can assign a role only when you hold every scope in it, and platform superusers are exempt from this rule. Tracecat refuses an assignment whose role carries a scope you lack, or adding a user to a group whose roles carry one, with Cannot grant scopes not held by the caller. You change a member’s roles from the organization Members page with Manage roles, which edits their organization-wide and workspace assignments. Without the rbac_addons entitlement you manage access with built-in roles from the organization Members page. See Custom roles and groups for custom roles, groups, and scopes.

Organization membership

A role assignment applies only to a user who is a member of the organization, and Tracecat rejects assigning a role or a group to a user without membership with User not found in organization. A signed-in user without an organization membership sees No organization access yet instead of their workspaces, with any pending invitations listed. Registration and sign-in without an invitation create no membership. On a single-tenant deployment, registration or sign-in enrolls a superuser into the default organization and repairs the organization-wide role of an existing member. An account that holds no membership needs an invitation or provisioning before it can open a workspace. Accepting an invitation creates organization membership and applies its role grants at their selected organization-wide or workspace scopes. Existing assignments at those scopes stay unchanged. When you invite an organization member from the platform admin console, acceptance creates membership alone. Membership alone carries baseline organization access, with no organization-wide role assigned. Workspace-scoped grants provide access to their workspaces. See User management for invitations.
  • See User management for registration, invitations, and organization membership.
  • See Custom roles and groups for custom roles, groups, custom scopes, and assignment management on the Access control page.
  • See Service accounts for machine identities that hold scopes directly, with no role.
  • See Architecture for how RBAC fits the identity and trust model.
  • See Organization audit logs for the rbac_role, rbac_group, rbac_assignment, and rbac_user_assignment events.